Definition
ISO 27001
International standard for an Information Security Management System (ISMS).
Where SOC 2 is American and process-attestation oriented, ISO 27001 is international and management-system oriented. Many enterprise European buyers will demand it. A typical SaaS target on a sell-side runs both. Diligence checks scope of certification, last surveillance audit, and any non-conformities raised.
See also